Singapore, US warn of latest Fortinet bug being exploited in wild
嗯,用户让我用中文总结一下这篇文章,控制在100字以内,而且不需要用“文章内容总结”或者“这篇文章”这样的开头。直接写描述就行。好的,我得先仔细读一下文章内容。 文章主要讲的是美国和新加坡的政府机构发布了紧急通知,警告一个影响Fortinet工具的漏洞被利用进行攻击。这个漏洞是由网络安全研究人员披露的。Fortinet公司已经发布了修复补丁,并且CISA给了联邦机构截止日期要求安装补丁。研究人员指出这个漏洞影响范围很广,可能被广泛利用。另外,攻击者可能选择在假期周末发动攻击,因为那时安全团队人手不足,容易被攻击得逞。 我需要把这些关键点浓缩到100字以内。首先提到美国和新加坡的政府警告,然后是Fortinet的漏洞被利用,CISA要求安装补丁,以及攻击者可能选择在假期发动攻击的情况。 可能的结构是:美国和新加坡政府警告Fortinet漏洞被利用,CISA要求安装补丁,并指出攻击者可能在假期发动攻击。 这样应该能控制在100字以内了。 </think> 美国和新加坡政府警告称,网络安全研究人员披露了一个影响Fortinet工具的严重漏洞(CVE-2026-35616),该漏洞正被用于网络攻击。Fortinet已发布修复补丁,CISA要求联邦机构尽快安装,并强调该漏洞可能被广泛利用。研究人员指出,攻击者可能选择假期周末发动攻击以增加成功几率。 2026-4-6 16:31:6 Author: therecord.media(查看原文) 阅读量:8 收藏

Government agencies in the U.S. and Singapore released urgent notices warning that a bug impacting a Fortinet tool is being exploited in attacks following a disclosure by cybersecurity researchers. 

The cybersecurity company Defused said it observed in-the-wild exploitation of CVE-2026-35616 last week and disclosed it to Fortinet. Fortinet explained in an advisory that the vulnerability carries a severity score of 9.1 out of 10 and urged customers to install a hotfix for the bug.  

The Cybersecurity and Infrastructure Security Agency (CISA) gave federal agencies until Thursday to apply the hotfix. 

“Please adhere to Fortinet's guidelines to assess exposure and mitigate risks. Check for signs of potential compromise on all internet accessible Fortinet products affected by this vulnerability,” CISA said. “Apply any final mitigations provided by the vendor as soon as they become available.”

Researchers warned that FortiClient EMS is used widely across many governments around the world and exposure to the bug may be wide. 

Benjamin Harris, CEO of cybersecurity firm watchTowr, said their honeypots began capturing exploitation of CVE-2026-35616 on March 31. He credited Fortinet with quickly releasing a fix for the bug, reflecting how urgently the company treated the vulnerability. 

“The timing of the ramp-up of in-the-wild exploitation of this zero-day is likely not coincidental. Attackers have shown repeatedly that holiday weekends are the best time to move,” Harris noted. 

“Security teams are at half strength, on-call engineers are distracted, and the window between compromise and detection stretches from hours to days. Easter, like any other holiday, represents opportunity.” 

He added that this is the second vulnerability in FortiClient EMS disclosed over the last three weeks, meaning customers will again have to rush to patch their platforms before attackers gain the upper hand. 

Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.


文章来源: https://therecord.media/singapore-us-warn-of-fortinet-bug-exploited
如有侵权请联系:admin#unsafe.sh